RyTech Innovation

Privacy policy

As of 27 August 2026

This is a non-binding convenience translation. The German version is authoritative.

1. Controller

RyTech Innovation Owner: Nikita Rybalka Ada-Lovelace-Straße 2 85521 Ottobrunn Germany

Phone: +49 151 42091353

Email: nikita@rytech-innovation.com

2. Data protection officer

No data protection officer has been appointed. The thresholds of § 38 BDSG (German Federal Data Protection Act) — as a rule at least 20 people constantly engaged in automated processing of personal data, or processing subject to a data protection impact assessment — are not met.

3. Your rights

You have the following rights regarding your personal data:

  • right of access (Art. 15 GDPR)
  • right to rectification (Art. 16 GDPR)
  • right to erasure (Art. 17 GDPR)
  • right to restriction of processing (Art. 18 GDPR)
  • right to data portability (Art. 20 GDPR)
  • right to object to processing (Art. 21 GDPR)
  • right to withdraw consent with effect for the future (Art. 7(3) GDPR)

4. Right to lodge a complaint with the supervisory authority

You have the right to lodge a complaint with a data protection supervisory authority. As the business seat is in Bavaria, the competent authority is:

Bayerisches Landesamt für Datenschutzaufsicht (BayLDA) Promenade 27 91522 Ansbach, Germany

www.lda.bayern.de

5. Hosting and server log files

The website is hosted on self-operated server infrastructure (located in Ottobrunn, Germany) and delivered via Cloudflare's content delivery network (see section 6). On each request, technical connection data is generated: requested resource (URL/path), date and time, HTTP status code, volume transferred, browser type and operating system (user agent), referrer (if transmitted) and, on error, a truncated IP address.

This data is processed only in the server's application log (the application container's standard output). It is not stored in a database, not merged with other sources, and is kept only for technical operation and error analysis; the log is capped at a fixed size and overwritten on a rolling basis (typically within a few days). The intermediary reverse proxy keeps no access log of its own. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in the technical provision, stability and security of the service).

6. Delivery via Cloudflare (processor)

For DNS resolution, TLS termination at the network edge and delivery via an outbound tunnel (Cloudflare Tunnel) we use Cloudflare. The provider is Cloudflare, Inc., 101 Townsend Street, San Francisco, CA 94107, USA. Cloudflare processes personal data (in particular IP address, connection and security data) as a processor on instructions, on the basis of Cloudflare's data processing addendum (Art. 28 GDPR).

An onward transfer to Cloudflare, Inc. in the USA (a third country) cannot be excluded. It is safeguarded by Cloudflare, Inc.'s certification under the EU-US Data Privacy Framework and, additionally, by the EU standard contractual clauses incorporated by Cloudflare. Legal basis: Art. 6(1)(f) GDPR. More information: cloudflare.com/privacypolicy.

7. Reach measurement (self-hosted, cookieless)

We operate a self-built reach measurement hosted on our own infrastructure (no third-party provider, no Google Analytics, no hosted Matomo). Per page view we record: requested path, language setting, referrer domain (external only), country (from Cloudflare's CF-IPCountry header, with no separate third-party geo-IP lookup), device type (mobile/desktop) and approximate time on page.

No cookie is set and no value is stored in or read from the browser's local storage. To distinguish unique visits within a single day, a visitor hash is formed: a SHA-256 value of IP address, user agent and a secret, automatically daily-rotating random value, truncated to 32 characters. The IP address itself is never stored. Because the daily random value is not retained, the hashes cannot be linked across days or reversed to a person; no device fingerprint (e.g. via canvas, fonts or WebGL) is formed.

Retention: 30 days, after which individual records are automatically deleted; no further aggregation takes place. The measurement honours the browser's "Do Not Track" setting — if set, no record is created.

Since this involves neither cookies nor access to information on the terminal equipment, and no IP address is stored, consent under § 25(1) TDDDG is not required. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in a data-minimising, aggregated analysis to improve the service).

8. Functional language-choice cookie

Only when you actively use the language switch (DE/EN) is a functional first-party cookie set (rytech_locale, lifetime 1 year) that stores only your language preference. It serves no analytics, tracking or profiling purpose and is technically required to provide the function you actively chose (§ 25(2) no. 2 TDDDG in conjunction with Art. 6(1)(f) GDPR). No consent banner is required for it.

9. Contact and contact form

We process the details you submit via the contact form to handle your enquiry. Mandatory fields are name, email address and message, plus acknowledgement of this privacy policy; company and phone number are optional.

The form contents are delivered to our mailbox by email via Google Workspace (see section 10) and are not additionally stored in a database. Only a technical record of receipt is logged locally (timestamp, language, delivery status, the daily IP hash from section 7) — without form contents; this record is deleted after at most 365 days. Internal follow-up processing runs on a self-operated automation component (n8n); this is our own processing, not the involvement of a third party.

Legal basis: Art. 6(1)(b) GDPR where the enquiry is directed at concluding or performing a contract, otherwise Art. 6(1)(f) GDPR (legitimate interest in answering enquiries). Correspondence is deleted once the enquiry has been conclusively handled and no statutory retention obligations apply (see section 12).

10. Google Workspace (email and scheduling)

We use Google Workspace for email and for scheduling intro calls. The EEA provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. The data processed is that contained in the email correspondence (name, company, email address, phone number where given, message content) and appointment data (name, email address, time).

On the contact page you can open an embedded Google scheduling widget (Google Calendar appointment scheduling) via the "Book a 30-minute intro call" button. It is not loaded automatically. Only when you actively click the button is the embed loaded from calendar.app.google / calendar.google.com; this transmits your IP address to Google and Google may set or read cookies on your device. Your deliberate click is itself the request for this service that you initiated (§ 25(2) no. 2 TDDDG); no separate consent banner is required for it. In Google's booking dialog you enter your name, email address and preferred time. The sole purpose is arranging the non-binding intro call. If you prefer not to use the scheduler, the contact form or the email address above are available.

The basis is the data processing addendum incorporated into every Google Workspace contract (processing on instructions, Art. 28 GDPR); processing is configured to the EU region. The legal basis for the booking is Art. 6(1)(b) GDPR (pre-contractual steps taken at your request), otherwise Art. 6(1)(f) GDPR (legitimate interest in efficient scheduling). A transfer to the USA (Google LLC) is safeguarded by Google's certification under the EU-US Data Privacy Framework and by EU standard contractual clauses. Email correspondence and appointment data are retained only for as long as needed to handle your enquiry or conduct the business relationship and for as long as statutory retention obligations apply; after that they are deleted as part of routine data management. More information: policies.google.com/privacy.

11. Fonts and external resources

All fonts used (IBM Plex Sans, IBM Plex Mono) are bundled at build time and served from our own server. At runtime no connection is made to Google Fonts or any other external content delivery network. Otherwise the website loads no external scripts, map or video embeds. The only exception is the Google scheduling widget described in section 10, which is loaded solely after your active click on the booking button; the corresponding Content-Security-Policy exception is limited to those two Google hosts.

12. Contracts, invoices, applications

Data processed in the context of quotes, contracts and invoices (client data, contacts, billing details) is processed to perform the contract and to meet statutory retention obligations. Legal basis: Art. 6(1)(b) and (c) GDPR. Retention in accordance with § 147 AO and § 257 HGB (six or ten years depending on the type of document), then erasure.

13. No automated decision-making

No automated decision-making, including profiling, within the meaning of Art. 22 GDPR takes place.